Content type · 3,589 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
Belgian DPA rejects delisting request for US government URL showing criminal conviction The data subject requested from a search engine (controller) the removal of a URL that appears when the data subject’s name is entered into the search engine. The URL points to… DOS-2025-04652 ·Belgium · Jun 8, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece · ·Art. 15 Jun 5, 2026
€1,153 Reda Naujokaitienė: Insufficient legal basis for data processing The Lithuanian Data Protection Authority (VDAI) fined Reda Naujokaitienė €1,153 on June 5, 2026, for insufficient legal basis for personal data processing in the health care… Lithuania · ·Art. 5, 6, 9 Jun 5, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece · ·Art. 5, 12, 15 +1 Jun 5, 2026
€90,000 Ypiresia 800 Teleperformance Single Member S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority fined Ypiresia 800 Teleperformance Single Member S.A. €90,000 for failing to implement sufficient technical and organizational measures to… Greece · ·Art. 5, 32 Jun 2, 2026
€45,000 MEDIATEL Telephone Information Services S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined MEDIATEL Telephone Information Services S.A. €45,000 for failing to implement sufficient technical and organizational measures… Greece · ·Art. 32 Jun 2, 2026
€320,000 Public Power Corporation S.A. (DEI): Insufficient legal basis for data processing The Hellenic Data Protection Authority (HDPA) fined Public Power Corporation S.A. (DEI) €320,000 for lacking a sufficient legal basis for data processing. The decision addresses… Greece · ·Art. 5, 32 Jun 2, 2026
€20,000 CQS S.A. Customer-Centric Services: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined CQS S.A. Customer-Centric Services €20,000 for failing to implement sufficient technical and organizational measures to ensure… Greece · ·Art. 32 Jun 2, 2026
€80,000 PRELUDE GROUP E.E.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined PRELUDE GROUP E.E. €80,000 for failing to implement sufficient technical and organizational measures to ensure information… Greece · ·Art. 28, 29, 32 Jun 2, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Jun 1, 2026
€1.8M Elkjøp AS: Insufficient legal basis for data processing Norwegian Supervisory Authority (Datatilsynet) fined Elkjøp AS €1,820,000 on 2026-06-01 for: Insufficient legal basis for data processing. Norway · ·Art. 5, 6, 12 Jun 1, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania · ·Art. 32, 33 May 29, 2026
€55,000 The data controller for the case is a government body called the Agency for Digital Italy (AgID) AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the… 419/2026 · ·Art. 5, 12, 14 +1 May 28, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy · May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 May 28, 2026
€3,930 Action Fit di Milano: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Action Fit di Milano €3,930 for violations of Articles 6(1)(a), 12, and 21(2) GDPR, relating to non-compliance with general… Italy · ·Art. 6, 12, 21 May 28, 2026
€1,400 Ristorante Carlo Menta s.r.l.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Ristorante Carlo Menta s.r.l. €1,400 for failing to adequately fulfill its information obligations under the GDPR. The… Italy · ·Art. 5, 13 May 28, 2026
€6,000 Municipality of Sciacca: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Sciacca €6,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy · ·Art. 5, 6 May 28, 2026
Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union · May 28, 2026
€3,000 Autonomous Region of Sardinia: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Autonomous Region of Sardinia €3,000 on May 28, 2026, for processing personal data without a sufficient legal basis. The… Italy · ·Art. 5, 6 May 28, 2026
€700 Rosetta Trastervere s.r.l.s.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Rosetta Trastervere s.r.l.s. €700 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy · ·Art. 5, 13 May 28, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy · ·Art. 5, 6, 25 +2 May 28, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy · ·Art. 5, 9 May 28, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. ·Art. 14, 25 ·Non-compliance with general data processing principles May 26, 2026
€4,958 District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined the District Governor of Lubartów €4,958 for failing to implement adequate technical and organizational measures to ensure information security, citing… Poland · ·Art. 5, 25, 28 +1 May 25, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland · ·Art. 24, 25, 28 +1 May 25, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland · ·Art. 5 May 22, 2026
€6,292 Private individual: Insufficient cooperation with supervisory authority The Polish National Personal Data Protection Office (UODO) fined a private individual €6,292 for failing to adequately cooperate with the supervisory authority during an… Poland · ·Art. 58, 83 May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom May 20, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland · ·Art. 5, 24, 25 +3 May 19, 2026
UODO reprimands mayor for disclosing data subject's data to company without legal basis The data subject requested the mayor of their place of residence (the controller) to provide them scans of contracts the city had concluded with certain companies and invoices… DS.523.2582.2024 ·Poland ·Art. 5, 6 May 18, 2026
€43,000 Lidl Italia S.r.l.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Lidl Italia S.r.l. €43,000 for insufficient fulfillment of data subjects' rights under Articles 5, 12, 15, and 18 of the… Italy · ·Art. 5, 12, 15 +1 May 14, 2026
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy · ·Art. 5, 14 May 14, 2026
€1,000 FeGi M&A Services s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined FeGi M&A Services s.r.l. €1,000 for non-compliance with general data processing principles under Article 5(1)(a) and Article… Italy · ·Art. 5, 14 May 14, 2026
€8,000 Municipality of Ventasso: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Ventasso €8,000 for violating the general data processing principles under Articles 5, 6, and 9 of the… Italy · ·Art. 5, 6, 9 May 14, 2026
€1,000 Danta di Cadore Hunting Reserve: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Danta di Cadore Hunting Reserve €1,000 for failing to adequately fulfill its information obligations regarding the… Italy · ·Art. 5, 6, 13 May 14, 2026
€30,000 Vortika s.r.l.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Vortika s.r.l. €30,000 for failing to adequately fulfill its information obligations under the GDPR in the health care… Italy · ·Art. 5, 13, 14 +1 May 14, 2026
€1,800 Municipality of Mirabella Imbaccari: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Mirabella Imbaccari €1,800 for processing personal data without a sufficient legal basis, in violation of… Italy · ·Art. 5, 6, 37 May 14, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy · ·Art. 5, 6, 7 +5 May 14, 2026
€180,000 Emirates: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Emirates €180,000 for insufficient fulfillment of its information obligations under the GDPR. The authority found that the… Italy · ·Art. 5, 12, 13 May 14, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy · ·Art. 5, 9, 13 +2 May 14, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium · ·Art. 5, 12, 13 +2 May 12, 2026
€86,000 Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Société Wallonne des Eaux €86,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium · ·Art. 5, 12, 13 +1 May 12, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
€177,000 Technology Company: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Technology Company €177,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium · ·Art. 5, 6, 12 +1 May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium · ·Art. 5, 12, 13 +2 May 8, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium · May 6, 2026
€2,802 IP-RS · 0609-42/2026/7 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·Art. 32 May 1, 2026